yoinka

Active Directory (AD) Engineer

Sysco

Global Service Center- Costa RicaMidH-1B sponsor company
Sign in to applyVerified 2h ago
Location
Global Service Center- Costa Rica
Work model
On-Site
Level
Mid
H-1B history
4 approvals (FY2023)
Posted
8h ago

Skills

AzureCybersecurity

About this role

JOB DESCRIPTION

The Active Directory Engineer is responsible for designing, implementing, securing, and maintaining enterprise-level Active Directory Domain Services (AD DS) and hybrid Microsoft Entra ID environments. This role ensures the availability, performance, security, and recoverability of identity infrastructure across complex, multi-domain and multi-forest environments. The engineer manages domain controllers, Group Policy Objects, directory replication, authentication services, and synchronization between on-premises Active Directory and Microsoft Entra ID. The position leads or supports upgrades, migrations, forest consolidations, automation, and disaster recovery initiatives while resolving advanced Kerberos, NTLM, DNS, and replication issues. The role partners closely with Cybersecurity, Identity and Access Management, Cloud, Network, Service Desk, and application teams to deliver secure and reliable identity services.

Key Responsibilities

Design, install, configure, and maintain Active Directory forests, domains, organizational units, trusts, sites, subnets, and domain controllers. Administer and optimize Active Directory Domain Services, including replication topology, Flexible Single Master Operations (FSMO) roles, schema, global catalog, and directory health. Develop, implement, and enforce Group Policy Objects (GPOs) to support security, configuration management, access controls, and enterprise standards. Harden Active Directory environments by applying security baselines, privileged access controls, tiered administration practices, auditing, and remediation of identified vulnerabilities. Manage hybrid identity services and synchronization between on-premises Active Directory and Microsoft Entra ID using Microsoft Entra Connect / Azure AD Connect. Troubleshoot and resolve complex authentication, authorization, replication, trust, DNS, Kerberos, NTLM, LDAP, and directory performance issues. Create and maintain advanced PowerShell scripts to automate user and group provisioning, object lifecycle management, reporting, health checks, and routine administration. Plan and execute Active Directory upgrades, domain or forest migrations, forest consolidations, tenant integration activities, and decommissioning initiatives. Develop, test, and maintain disaster recovery procedures for domain controllers, schema, trusts, DNS-integrated zones, and critical identity services. Monitor Active Directory capacity, availability, security events, and service health; identify trends and implement preventive or corrective actions. Provide technical leadership and subject-matter expertise for identity-related incidents, problems, changes, and major infrastructure projects. Produce and maintain accurate technical documentation, including architecture diagrams, operating procedures, configuration standards, recovery plans, and knowledge articles. Collaborate with Cybersecurity, IAM, Cloud, Network, Server, Service Desk, and application teams to ensure identity solutions meet business, operational, and compliance requirements. Participate in change management, incident response, root-cause analysis, and continuous improvement activities in accordance with established IT service management practices. ​ Qualifications Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field; equivalent relevant professional experience may be considered. 3 years of hands-on experience administering and engineering Microsoft Active Directory in enterprise environments. Excellent communication skills in English (B2+ or higher) and ability to collaborate across functions and geographies. Experience supporting large-scale, multi-domain, multi-forest, or geographically distributed Active Directory environments. Experience managing Active Directory infrastructure, including domain controllers, forests, trusts, organizational units, replication, and Group Policy. Experience supporting hybrid identity

Active Directory (AD) Engineer at Sysco — Global Service Center- Costa Rica | Yoinka